Kibana 中存在缺失授权检查(CWE-862),可能导致通过权限滥用(CAPEC-122)造成信息泄露。具体而言,在 Kibana 实体存储(Entity Store)的配置操作中,未应用相应的授权控制,使得拥有提升权限的已认证用户可以间接触发一个后台任务,从该用户本无权限访问的 Elasticsearch 索引中读取数据,而这些索引中衍生出的实体数据随后通过实体存储的输出暴露出来。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78604 | 7.8 HIGH | Incorrect Permission Assignment for Critical Resource in Elastic Agent Leading to Local Pr |
| CVE-2026-78590 | 7.3 HIGH | Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori |
| CVE-2026-78588 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Filebeat Leading to Denial of Serv |
| CVE-2026-78586 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic |
| CVE-2026-78599 | 6.5 MEDIUM | Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources |
| CVE-2026-78591 | 6.3 MEDIUM | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana L |
| CVE-2026-78598 | 5.4 MEDIUM | Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine |
| CVE-2026-78609 | 5.4 MEDIUM | Incorrect Authorization in Elastic Cloud on Kubernetes Leading to Unauthorized Modificatio |
| CVE-2026-78602 | 5.3 MEDIUM | Improper Limitation of a Pathname to a Restricted Directory in Elastic Maps Server Leading |
| CVE-2026-78594 | 4.9 MEDIUM | Improper Handling of Highly Compressed Data in APM Server Leading to Persistent Denial of |
| CVE-2026-82293 | 4.3 MEDIUM | Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption |
| CVE-2026-78584 | 4.3 MEDIUM | Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure |
| CVE-2026-78600 | 3.5 LOW | Incomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cross-Namespace |
| CVE-2026-78587 | 3.1 LOW | Incorrect Authorization in Fleet Server Leading to Denial of Service of Agent Upload Opera |
No comments yet